Automox
Cloud-native patch management (SaaS, no on-prem infrastructure)
Patch what's patchable, mitigate what's not - automating OS and third-party patching, configuration, and custom endpoint automation from one cloud platform.
- SaaS (cloud-native)Deployment
- No / cloud-onlyOn-prem option
- Not statedDistribution
- YesPublished price
- Classification
- Official/Verified: A cloud-native SaaS, agent-based, cross-platform (Windows/macOS/Linux) endpoint patch- and configuration-management platform with no on-premises servers.
- Operating systems patched
- Official/Verified: Windows (11 and 10, incl. ARM64; Server 2025 through 2012 R2), macOS (Tahoe/Sequoia/Sonoma on Intel and Apple Silicon), and a broad Linux range (RHEL, Fedora, CentOS Stream, Rocky, Alma, Oracle Linux, Amazon Linux, Debian, Ubuntu, SLES, and others).
- Third-party application patching
- Official/Verified: Yes. Automox's patching pages cite 'over 580 third-party software titles' (e.g., Adobe, Firefox, Chrome), while its pricing page lists '630+ third-party patching titles' - both are the vendor's own figures.
- Patch discovery / vulnerability visibility
- Official/Verified: Inventories hardware, software, outstanding patches, and configuration, flagging non-compliant devices as 'Needs Attention.' Vulnerability Sync ingests third-party scanner findings (named: CrowdStrike, Tenable, Qualys; plus any scanner that exports a compatible CSV) and drives remediation, feeding status back into the findings view.
- Automation & scheduling
- Official/Verified: Policy types include Patch All, Patch Only, Patch All Except, Manual Approval, By Severity, and Advanced Policy; every policy sets a schedule. Worklets (custom automation scripts) can perform any scriptable action, including mass rollback of patches. The pricing page cites 432+ prebuilt Worklet scripts and a FixNow immediate-execution capability in the Enterprise tier.
- Testing / staging
- Official/Verified: Staged/test-group deployment is achieved through device Groups plus the Manual Approval policy type. Automox does not use named 'ring/pilot' terminology on its official pages.
- Reboot management
- Official/Verified: Restart notifications with end-user deferral (defaults of 1/4/8 hours and up to 6 deferrals), configurable notification duration (15 minutes-8 hours), and automatic deferral if a notification is ignored; after deferrals are exhausted the device restarts within 15 minutes. Supported on Windows and macOS.
- Rollback / uninstall
- Official/Verified: Patch rollback is supported on Windows only (Windows 7 / Server 2008 R2 or newer) via a console 'Roll Back' bulk action and a verified Rollback Worklet; not all patches can be rolled back (must be marked uninstallable by Microsoft). App uninstall is available via Worklets. Automox notes rollback is 'an inherently risky process.'
- Content distribution
- No peer-to-peer, relay, or WAN/bandwidth-optimization feature is stated on Automox's official pages. OS patches are pulled directly from native OS update services; third-party patches are cached by Automox and malware-scanned before deployment.
- Reporting & compliance
- Official/Verified: A unified cloud console gives centralized inventory and patch-status visibility and a 'Needs Attention' compliance state. Detailed report/dashboard specifics beyond this are not itemized on the pages reviewed.
- ITSM / ticketing integration
- Official/Verified: ServiceNow Service Graph Connector imports Automox device data into the ServiceNow CMDB (device name, serial, OS version, IP, CPU, MAC, and more). A first-party Jira integration is not confirmed on the official docs.
- Remote control / remote access
- Official/Verified: Yes - Remote Control in the Splashtop-powered Remote Tools suite (Remote Control, Remote Command, File Transfer, System Tools), surfaced inside the Automox console.
- Agent model
- Official/Verified: A lightweight agent installed on managed devices (approx. 100-150 MB memory, ~100-290 MB disk depending on OS); Windows requires .NET 3.51+ and PowerShell 5.1+. No on-prem infrastructure is required - the platform is cloud-only.
- Scale
- Official/Verified: No hard endpoint limit is published; Automox states it suits organizations managing 'ten devices or ten thousand,' running on a clustered AWS architecture that scales on demand. Specific maximum-endpoint or benchmark figures are not stated.
- Data residency / certifications
- Official/Verified: Hosted on AWS using Regions and Availability Zones; specific named hosting regions are not stated on the pages reviewed. Attestations named on official pages include SOC 2 Type II, SOC 3, CSA STAR, PCI DSS v4, GDPR, EU-US Data Privacy Framework, and TX-RAMP; Automox is a CISA Secure by Design signatory. FedRAMP and ISO 27001 are not stated.
- Pricing
- Published Price: Patch OS is $1 per endpoint/month with an annual commitment (Windows, macOS, and Linux OS patching). Automate Essentials and Automate Enterprise are custom-priced. Monthly (no-commitment) billing is available; annual saves 25%.The $1/endpoint/month figure is the Patch OS tier; third-party patching at scale and advanced automation sit in the custom-quoted tiers.
- Company-size fit
- EVULNABLE Assessment: Automox's transparent $1/endpoint Patch OS tier, cloud-only model, and cross-OS coverage fit SMB and mid-market IT teams well, and the platform is used at enterprise scale - so it spans SMB through enterprise. As with any cloud-only tool, check it against any on-prem or air-gapped requirement.
- How the vendor positions it
- Automox positions the product for 'IT and security teams' managing endpoints 'anywhere with an internet connection,' explicitly spanning organizations 'managing ten devices or ten thousand,' including MSPs.
Last verified: September 6, 2026 Confirm current details directly with the vendor.
